๐Ÿ” CVE Alert

CVE-2026-54174

HIGH 8.3

melange: Incomplete package integrity verification allows data section substitution

CVSS Score
8.3
EPSS Score
0.0%
EPSS Percentile
0th

melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but never verified the data section hash (the actual package files that get installed). An attacker who could compromise a mirror, poison a cache, or MITM a package fetch could substitute arbitrary file contents while the control hash check still passed. Apko version 1.2.9 and melange version 0.50.4 contain a fix.

CWE CWE-354 CWE-345
Vendor chainguard-dev
Product melange
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for chainguard-dev melange

Be the first to know when new high vulnerabilities affecting chainguard-dev melange are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

chainguard-dev / melange
< 0.50.4
chainguard-dev / apko
< 1.2.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/chainguard-dev/melange/security/advisories/GHSA-fpg8-7664-jc5q